Start with the risk itself

A project risk is something that might happen and would affect the project if it did. If the problem has already happened, it is usually an issue rather than a risk.

A useful risk description normally includes the cause, the uncertain event and the possible effect. For example: user testing has started later than planned, so critical defects may remain unresolved at launch, which could delay release or cause operational problems.

Likelihood and impact

Most project risk matrices score two things: how likely the risk is to happen and how serious the effect would be. A common approach is a 1 to 5 scale for each, with the two numbers multiplied together.

The arithmetic is simple. The judgement behind it is the important part. If your organisation already has definitions for each score or an agreed risk matrix, use those instead of inventing your own.

Risk score = likelihood × impact

A score helps you compare risks and decide what needs attention. It does not remove the need to explain why the ratings were chosen.

Current risk and residual risk

Current risk is the exposure you're carrying now. Residual risk (or post-mitigation risk) is the level of risk you expect to be left with after the agreed mitigation actions have been completed and are having the intended effect.

Do not reduce a residual score just because a mitigation has been written into the register. Reduce it when there is a reasonable basis for believing the mitigation will actually change the likelihood or impact.

Mitigation, contingency and triggers

Mitigation
Something you do before the risk happens to reduce its likelihood or impact.
Contingency
The action you plan to take if the risk actually happens.
Trigger
The event or threshold that tells you the contingency should start.
Risk owner
The person accountable for keeping the risk under review and making sure the agreed response happens.

A simple worked example

Risk: a key business process may not be ready for the planned launch date because user testing has started later than expected. Current assessment: likelihood 4, impact 4, score 16. Mitigation: prioritise the critical test scenarios, add extra test sessions and review progress twice a week. Residual assessment: likelihood 2, impact 4, score 8, if testing catches up as planned. Contingency: delay the affected part of the launch and release it separately once testing is complete. Trigger: fewer than 80% of critical test scenarios have passed one week before launch.

What to include in a risk register

At a minimum, record the risk, the risk owner, the current likelihood and impact scores, the mitigation actions, the residual likelihood and impact scores, any contingency, and the next review date. The register should help you manage the risks, not become a document that is updated for its own sake.

Free Excel resource

Download the PMZ project risk register

The workbook gives you a practical risk register you can use on your own project, with current and residual scoring, mitigation and contingency fields, owners, review dates, a worked example and a simple scoring guide. No sign-up is required.

A more detailed version of the risk register is included in the First 30 Days toolkit.

Download the free Excel risk register

Related PMZ resource

Check the wider health of your project

Run the project health check

This is practical guidance, not a replacement for your organisation's risk policy, governance or escalation rules.